CVE-2020-20139
MEDIUMFlexmonster Pivot Table & Charts 2.7.17 - Cross-Site Scripting in Remote JSON Component
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-20139. PoCs published by Marco Nappi.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in Flexmonster Pivot Table & Charts 2.7.17 via the 'path' parameter in file_specs.php. The payload uses an SVG onload event to trigger arbitrary JavaScript execution.
Description
Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.
Exploits (1)
exploitdb
WORKING POC
by Marco Nappi · textwebappsmultiple
https://www.exploit-db.com/exploits/49305
This exploit demonstrates a reflected XSS vulnerability in Flexmonster Pivot Table & Charts 2.7.17 via the 'path' parameter in file_specs.php. The payload uses an SVG onload event to trigger arbitrary JavaScript execution.
Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:
Flexmonster Pivot Table & Charts 2.7.17
No auth needed
Prerequisites:
User interaction to navigate to a crafted URL
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026
Full analysis →
References (1)
Core 1
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://packetstormsecurity.com/files/160604/Flexmonster-Pivot-Table-And-Charts-2.7.17-Cross-Site-Scripting.html
Scores
CVSS v3
6.1
EPSS
0.0162
EPSS Percentile
72.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
flexmonster/pivot_table_\&_charts
2.7.17
Published
Dec 17, 2020
Tracked Since
Feb 18, 2026